information and transparency
Privacy
noortio needs to see a page to audit it. This policy explains, in plain language, what data enters that process and what changes when you create an account.
Updated on August 20, 2026
Data that enters the product
When you start an audit, we handle the submitted URL, the publicly accessible content of that page, DOM measurements, and captures in desktop, mobile and full page. The report stores scores, findings, evidence and the capture date.
If you create an account, the authentication provider also gives us a user identifier and, when available, the associated email. We never ask for your site's password, analytics data or dashboard access.
How this data is used
- capturing and measuring the requested page;
- generating the diagnosis and the order of fixes;
- saving audits to your account when you ask;
- comparing runs of the same page and showing progress;
- limiting abuse and keeping the service available.
We don't sell your account's data and we don't use captured pages for behavioral advertising.
Services involved
The flow uses specialized providers for authentication, database, image storage, rate limiting, page capture and model-assisted judgment. Each provider receives only the slice it needs to run its step.
The audited page may load resources from its own providers during the capture, the same way it would load in a regular browser.
Retention and your control
Without an account, the seals that allow saving the audit stay in the tab for up to 24 hours and may disappear sooner if you close the tab or clear your browser data. With an account, projects, reports and captures remain tied to your user to build history and enable comparisons.
You can stop using the service at any time. Data deletion and export are still handled by request while there isn't yet an automatic control inside the product.
Security and limits
Temporary reports are sealed on the server, and every read from the authenticated area is filtered by user. Even so, no system is immune to failures. Don't submit private URLs, tokens in query strings, or pages that depend on credentials: the auditor was designed for public content.
To handle a privacy request, use the channel through which you got access to noortio and provide the account's email. Never send passwords or access keys.